Static

Validation test suite using one of the DNS options available in an upstream server

DNS-over-HTTPS Server

Description

Configures DUT0 to connect, using DNS-over-HTTPS (DoH) over an upstream server.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https hash a40f12bde09499f71a7f233a3d6b7dab165d2d4b8f21456db726f7a863d7a414
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set service dns resolver local
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

(?m)^.*\[RD\] OK \(DoH\) - rtt: \d+ms$
Show output
Jul 24 10:15:35.283582 osdx systemd-journald[2180]: Runtime Journal (/run/log/journal/3a8dbab828fc40a183893e468c03e10b) is 1.8M, max 13.8M, 11.9M free.
Jul 24 10:15:35.286353 osdx systemd-journald[2180]: Received client request to rotate journal, rotating.
Jul 24 10:15:35.286411 osdx systemd-journald[2180]: Vacuuming done, freed 0B of archived journals from /run/log/journal/3a8dbab828fc40a183893e468c03e10b.
Jul 24 10:15:35.293203 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal clear'.
Jul 24 10:15:35.511227 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system coredump delete all'.
Jul 24 10:15:35.745528 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:15:35.852861 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Jul 24 10:15:35.947972 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Jul 24 10:15:36.016938 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'.
Jul 24 10:15:36.118131 osdx ubnt-cfgd[442098]: inactive
Jul 24 10:15:36.142076 osdx INFO[442107]: FRR daemons did not change
Jul 24 10:15:36.174352 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Jul 24 10:15:36.223011 osdx WARNING[442178]: No supported link modes on interface eth0
Jul 24 10:15:36.224730 osdx modulelauncher[442178]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Jul 24 10:15:36.224748 osdx modulelauncher[442178]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Jul 24 10:15:36.226135 osdx modulelauncher[442178]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --
Jul 24 10:15:36.226143 osdx modulelauncher[442178]: Command '/sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --' returned non-zero exit status 75.
Jul 24 10:15:36.420860 osdx cfgd[1923]: [414651]Completed change to active configuration
Jul 24 10:15:36.421429 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:15:36.447201 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.
Jul 24 10:15:36.598079 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Jul 24 10:15:36.668358 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal show | cat'.
Jul 24 10:15:36.857527 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:15:36.926329 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Jul 24 10:15:37.027068 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Jul 24 10:15:37.098416 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Jul 24 10:15:37.187959 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Jul 24 10:15:37.257184 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https hash a40f12bde09499f71a7f233a3d6b7dab165d2d4b8f21456db726f7a863d7a414'.
Jul 24 10:15:37.409442 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns resolver local'.
Jul 24 10:15:37.524862 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'.
Jul 24 10:15:37.623888 osdx ubnt-cfgd[442285]: inactive
Jul 24 10:15:37.648731 osdx INFO[442294]: FRR daemons did not change
Jul 24 10:15:37.663252 osdx ca-certificates[442310]: Updating certificates in /etc/ssl/certs...
Jul 24 10:15:38.232870 osdx ubnt-cfgd[443322]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Jul 24 10:15:38.240879 osdx ca-certificates[443328]: 1 added, 0 removed; done.
Jul 24 10:15:38.243785 osdx ca-certificates[443334]: Running hooks in /etc/ca-certificates/update.d...
Jul 24 10:15:38.247508 osdx ca-certificates[443336]: done.
Jul 24 10:15:38.366666 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Jul 24 10:15:38.375661 osdx cfgd[1923]: [414651]Completed change to active configuration
Jul 24 10:15:38.376189 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:15:38.394033 osdx dnscrypt-proxy[443392]: [2026-07-24 10:15:38] [NOTICE] dnscrypt-proxy 2.0.45
Jul 24 10:15:38.394284 osdx dnscrypt-proxy[443392]: [2026-07-24 10:15:38] [NOTICE] Network connectivity detected
Jul 24 10:15:38.394325 osdx dnscrypt-proxy[443392]: [2026-07-24 10:15:38] [NOTICE] Dropping privileges
Jul 24 10:15:38.397476 osdx dnscrypt-proxy[443392]: [2026-07-24 10:15:38] [NOTICE] Network connectivity detected
Jul 24 10:15:38.397543 osdx dnscrypt-proxy[443392]: [2026-07-24 10:15:38] [NOTICE] Now listening to 127.0.0.1:53 [UDP]
Jul 24 10:15:38.397543 osdx dnscrypt-proxy[443392]: [2026-07-24 10:15:38] [NOTICE] Now listening to 127.0.0.1:53 [TCP]
Jul 24 10:15:38.397543 osdx dnscrypt-proxy[443392]: [2026-07-24 10:15:38] [NOTICE] Firefox workaround initialized
Jul 24 10:15:38.397596 osdx dnscrypt-proxy[443392]: [2026-07-24 10:15:38] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpmiceyhxf]
Jul 24 10:15:38.397615 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.
Jul 24 10:15:38.547994 osdx dnscrypt-proxy[443392]: [2026-07-24 10:15:38] [NOTICE] [RD] OK (DoH) - rtt: 107ms
Jul 24 10:15:38.547994 osdx dnscrypt-proxy[443392]: [2026-07-24 10:15:38] [NOTICE] Server with the lowest initial latency: RD (rtt: 107ms)
Jul 24 10:15:38.547994 osdx dnscrypt-proxy[443392]: [2026-07-24 10:15:38] [NOTICE] dnscrypt-proxy is ready - live servers: 1

Step 3: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

DNS-over-HTTPS Server Trusting Fails

Description

Configures DUT0 to connect, using DNS-over-HTTPS (DoH) over an upstream without setting up certificates.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Note

The above commands set the network topology to interact with the DNS server

Step 2: Modify the following configuration lines in DUT0 :

set service dns proxy server-name RD
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set service dns resolver local

Note

The above commands set up the DNS server to be used.

Step 3: Run the command system journal show | cat on DUT0 and check whether the output contains the following tokens:

: x509: certificate signed by unknown authority
Show output
Jul 24 10:15:45.308771 osdx systemd-journald[2180]: Runtime Journal (/run/log/journal/3a8dbab828fc40a183893e468c03e10b) is 1.8M, max 13.8M, 11.9M free.
Jul 24 10:15:45.309221 osdx systemd-journald[2180]: Received client request to rotate journal, rotating.
Jul 24 10:15:45.309251 osdx systemd-journald[2180]: Vacuuming done, freed 0B of archived journals from /run/log/journal/3a8dbab828fc40a183893e468c03e10b.
Jul 24 10:15:45.318317 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal clear'.
Jul 24 10:15:45.531015 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system coredump delete all'.
Jul 24 10:15:45.799049 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:15:45.945488 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Jul 24 10:15:45.999526 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Jul 24 10:15:46.106988 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'.
Jul 24 10:15:46.168807 osdx ubnt-cfgd[445165]: inactive
Jul 24 10:15:46.195168 osdx INFO[445174]: FRR daemons did not change
Jul 24 10:15:46.225148 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Jul 24 10:15:46.272732 osdx WARNING[445245]: No supported link modes on interface eth0
Jul 24 10:15:46.274196 osdx modulelauncher[445245]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Jul 24 10:15:46.274208 osdx modulelauncher[445245]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Jul 24 10:15:46.275381 osdx modulelauncher[445245]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --
Jul 24 10:15:46.275390 osdx modulelauncher[445245]: Command '/sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --' returned non-zero exit status 75.
Jul 24 10:15:46.491744 osdx cfgd[1923]: [414651]Completed change to active configuration
Jul 24 10:15:46.492357 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:15:46.520620 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.
Jul 24 10:15:46.687344 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Jul 24 10:15:46.760074 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal show | cat'.
Jul 24 10:15:46.962160 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:15:47.020312 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Jul 24 10:15:47.136867 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'.
Jul 24 10:15:47.189255 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:15:47.255290 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.
Jul 24 10:15:47.424415 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:15:47.497846 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Jul 24 10:15:47.591675 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Jul 24 10:15:47.647757 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Jul 24 10:15:47.736705 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns resolver local'.
Jul 24 10:15:47.801832 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show changes'.
Jul 24 10:15:47.901742 osdx ubnt-cfgd[445359]: inactive
Jul 24 10:15:47.924890 osdx INFO[445366]: FRR daemons did not change
Jul 24 10:15:48.033664 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Jul 24 10:15:48.042974 osdx cfgd[1923]: [414651]Completed change to active configuration
Jul 24 10:15:48.043721 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:15:48.054437 osdx dnscrypt-proxy[445424]: [2026-07-24 10:15:48] [NOTICE] dnscrypt-proxy 2.0.45
Jul 24 10:15:48.054692 osdx dnscrypt-proxy[445424]: [2026-07-24 10:15:48] [NOTICE] Network connectivity detected
Jul 24 10:15:48.054765 osdx dnscrypt-proxy[445424]: [2026-07-24 10:15:48] [NOTICE] Dropping privileges
Jul 24 10:15:48.056916 osdx dnscrypt-proxy[445424]: [2026-07-24 10:15:48] [NOTICE] Network connectivity detected
Jul 24 10:15:48.056981 osdx dnscrypt-proxy[445424]: [2026-07-24 10:15:48] [NOTICE] Now listening to 127.0.0.1:53 [UDP]
Jul 24 10:15:48.056981 osdx dnscrypt-proxy[445424]: [2026-07-24 10:15:48] [NOTICE] Now listening to 127.0.0.1:53 [TCP]
Jul 24 10:15:48.056981 osdx dnscrypt-proxy[445424]: [2026-07-24 10:15:48] [NOTICE] Firefox workaround initialized
Jul 24 10:15:48.056981 osdx dnscrypt-proxy[445424]: [2026-07-24 10:15:48] [NOTICE] Loading the set of cloaking rules from [/tmp/tmphsq0whi9]
Jul 24 10:15:48.087574 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.
Jul 24 10:15:48.153224 osdx dnscrypt-proxy[445424]: [2026-07-24 10:15:48] [ERROR] Get "https://remote.dns/dns-query?dns=yv4BAAABAAAAAAABAAACAAEAACkQAAAAAAAAFAAMABByt5UXz7zbfyxAdH_NT6yr": x509: certificate signed by unknown authority
Jul 24 10:15:48.153224 osdx dnscrypt-proxy[445424]: [2026-07-24 10:15:48] [NOTICE] dnscrypt-proxy is waiting for at least one server to be reachable

Step 4: Run the command show host lookup teldat.com type A on DUT0 and expect the following output:

Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
;; communications error to 127.0.0.1#53: timed out
;; no servers could be reached
  CLI Error: Command error

Note

The above command attempts to resolve the hostname but fails because the certificate cannot be verified


DNS-over-HTTPS Server Trusting

Description

Configures DUT0 to connect, using DNS-over-HTTPS (DoH) over an upstream without checking its certificate authority.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Note

The above commands set the network topology to interact with the DNS server

Step 2: Modify the following configuration lines in DUT0 :

set service dns proxy server-name RD
set service dns proxy ssl-allow-insecure
set service dns proxy static RD protocol dns-over-https host name remote.dns
set service dns proxy static RD protocol dns-over-https ip 10.215.168.1
set service dns resolver local

Note

The above commands set up the DNS server to be used, we skip certificate validation using set service dns proxy ssl-allow-insecure

Step 3: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

(?m)^.*\[RD\] OK \(DoH\) - rtt: \d+ms$
Show output
Jul 24 10:15:58.322913 osdx systemd-journald[2180]: Runtime Journal (/run/log/journal/3a8dbab828fc40a183893e468c03e10b) is 2.2M, max 13.8M, 11.5M free.
Jul 24 10:15:58.326769 osdx systemd-journald[2180]: Received client request to rotate journal, rotating.
Jul 24 10:15:58.326836 osdx systemd-journald[2180]: Vacuuming done, freed 0B of archived journals from /run/log/journal/3a8dbab828fc40a183893e468c03e10b.
Jul 24 10:15:58.332359 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal clear'.
Jul 24 10:15:58.628714 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system coredump delete all'.
Jul 24 10:15:58.924284 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:15:59.025142 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Jul 24 10:15:59.100016 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Jul 24 10:15:59.228300 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'.
Jul 24 10:15:59.296694 osdx ubnt-cfgd[445724]: inactive
Jul 24 10:15:59.323989 osdx INFO[445733]: FRR daemons did not change
Jul 24 10:15:59.354806 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Jul 24 10:15:59.408127 osdx WARNING[445804]: No supported link modes on interface eth0
Jul 24 10:15:59.409679 osdx modulelauncher[445804]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Jul 24 10:15:59.409692 osdx modulelauncher[445804]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Jul 24 10:15:59.411097 osdx modulelauncher[445804]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --
Jul 24 10:15:59.411137 osdx modulelauncher[445804]: Command '/sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --' returned non-zero exit status 75.
Jul 24 10:15:59.629663 osdx cfgd[1923]: [414651]Completed change to active configuration
Jul 24 10:15:59.630219 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:15:59.646150 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.
Jul 24 10:15:59.800501 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Jul 24 10:15:59.882937 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal show | cat'.
Jul 24 10:16:00.074437 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:16:00.189823 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Jul 24 10:16:00.337680 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'.
Jul 24 10:16:00.405631 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:16:00.464418 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.
Jul 24 10:16:00.633981 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:16:00.704757 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Jul 24 10:16:00.797181 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https host name remote.dns'.
Jul 24 10:16:00.855254 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-over-https ip 10.215.168.1'.
Jul 24 10:16:00.955289 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy ssl-allow-insecure'.
Jul 24 10:16:01.011970 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns resolver local'.
Jul 24 10:16:01.173400 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show changes'.
Jul 24 10:16:01.238497 osdx ubnt-cfgd[445919]: inactive
Jul 24 10:16:01.265471 osdx INFO[445926]: FRR daemons did not change
Jul 24 10:16:01.375101 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Jul 24 10:16:01.382898 osdx cfgd[1923]: [414651]Completed change to active configuration
Jul 24 10:16:01.383392 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:16:01.395935 osdx dnscrypt-proxy[445984]: [2026-07-24 10:16:01] [NOTICE] dnscrypt-proxy 2.0.45
Jul 24 10:16:01.396153 osdx dnscrypt-proxy[445984]: [2026-07-24 10:16:01] [NOTICE] Network connectivity detected
Jul 24 10:16:01.396295 osdx dnscrypt-proxy[445984]: [2026-07-24 10:16:01] [NOTICE] Dropping privileges
Jul 24 10:16:01.398748 osdx dnscrypt-proxy[445984]: [2026-07-24 10:16:01] [NOTICE] Network connectivity detected
Jul 24 10:16:01.398809 osdx dnscrypt-proxy[445984]: [2026-07-24 10:16:01] [NOTICE] Now listening to 127.0.0.1:53 [UDP]
Jul 24 10:16:01.398809 osdx dnscrypt-proxy[445984]: [2026-07-24 10:16:01] [NOTICE] Now listening to 127.0.0.1:53 [TCP]
Jul 24 10:16:01.398809 osdx dnscrypt-proxy[445984]: [2026-07-24 10:16:01] [NOTICE] Firefox workaround initialized
Jul 24 10:16:01.398809 osdx dnscrypt-proxy[445984]: [2026-07-24 10:16:01] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpf4i51aa1]
Jul 24 10:16:01.408959 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.
Jul 24 10:16:01.551163 osdx dnscrypt-proxy[445984]: [2026-07-24 10:16:01] [NOTICE] [RD] OK (DoH) - rtt: 117ms
Jul 24 10:16:01.551163 osdx dnscrypt-proxy[445984]: [2026-07-24 10:16:01] [NOTICE] Server with the lowest initial latency: RD (rtt: 117ms)
Jul 24 10:16:01.551163 osdx dnscrypt-proxy[445984]: [2026-07-24 10:16:01] [NOTICE] dnscrypt-proxy is ready - live servers: 1
Jul 24 10:16:01.566368 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal show | cat'.

Step 4: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

DNS-over-HTTPS Server With Stamp

Description

Configures DUT0 to connect, using DNS-over-HTTPS (DoH) over an upstream server (generating a DNS stamp and using it to configure the connection).

Scenario

Step 1: Run the command service dns proxy stamp calculate dns-over-https host-name remote.dns host-path /dns-query host-port 443 ip 10.215.168.1 hash a40f12bde09499f71a7f233a3d6b7dab165d2d4b8f21456db726f7a863d7a414 on DUT0 and expect the following output:

Show output
sdns://AgAAAAAAAAAADDEwLjIxNS4xNjguMSCkDxK94JSZ9xp_Izo9a32rFl0tS48hRW23JveoY9ekFApyZW1vdGUuZG5zCi9kbnMtcXVlcnk

Step 2: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy server-name RD
set service dns proxy static RD stamp 'sdns://AgAAAAAAAAAADDEwLjIxNS4xNjguMSCkDxK94JSZ9xp_Izo9a32rFl0tS48hRW23JveoY9ekFApyZW1vdGUuZG5zCi9kbnMtcXVlcnk'
set service dns resolver local
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

(?m)^.*\[RD\] OK \(DoH\) - rtt: \d+ms$
Show output
Jul 24 10:16:09.328384 osdx systemd-journald[2180]: Runtime Journal (/run/log/journal/3a8dbab828fc40a183893e468c03e10b) is 1.8M, max 13.8M, 11.9M free.
Jul 24 10:16:09.331174 osdx systemd-journald[2180]: Received client request to rotate journal, rotating.
Jul 24 10:16:09.331263 osdx systemd-journald[2180]: Vacuuming done, freed 0B of archived journals from /run/log/journal/3a8dbab828fc40a183893e468c03e10b.
Jul 24 10:16:09.339773 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal clear'.
Jul 24 10:16:09.577942 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system coredump delete all'.
Jul 24 10:16:09.842716 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:16:09.952490 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Jul 24 10:16:10.028553 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Jul 24 10:16:10.157037 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'.
Jul 24 10:16:10.232592 osdx ubnt-cfgd[446289]: inactive
Jul 24 10:16:10.261653 osdx INFO[446298]: FRR daemons did not change
Jul 24 10:16:10.295175 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Jul 24 10:16:10.347135 osdx WARNING[446369]: No supported link modes on interface eth0
Jul 24 10:16:10.348688 osdx modulelauncher[446369]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Jul 24 10:16:10.348701 osdx modulelauncher[446369]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Jul 24 10:16:10.349922 osdx modulelauncher[446369]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --
Jul 24 10:16:10.349930 osdx modulelauncher[446369]: Command '/sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --' returned non-zero exit status 75.
Jul 24 10:16:10.557702 osdx cfgd[1923]: [414651]Completed change to active configuration
Jul 24 10:16:10.558302 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:16:10.578127 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.
Jul 24 10:16:10.729794 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Jul 24 10:16:10.816366 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal show | cat'.
Jul 24 10:16:10.960473 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'service dns proxy stamp calculate dns-over-https host-name remote.dns host-path /dns-query host-port 443 ip 10.215.168.1 hash a40f12bde09499f71a7f233a3d6b7dab165d2d4b8f21456db726f7a863d7a414'.
Jul 24 10:16:11.112977 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:16:11.179521 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Jul 24 10:16:11.294347 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Jul 24 10:16:11.361042 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy static RD stamp sdns://AgAAAAAAAAAADDEwLjIxNS4xNjguMSCkDxK94JSZ9xp_Izo9a32rFl0tS48hRW23JveoY9ekFApyZW1vdGUuZG5zCi9kbnMtcXVlcnk'.
Jul 24 10:16:11.462094 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns resolver local'.
Jul 24 10:16:11.583021 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'.
Jul 24 10:16:11.676371 osdx ubnt-cfgd[446477]: inactive
Jul 24 10:16:11.702067 osdx INFO[446486]: FRR daemons did not change
Jul 24 10:16:11.719071 osdx ca-certificates[446502]: Updating certificates in /etc/ssl/certs...
Jul 24 10:16:12.324146 osdx ubnt-cfgd[447514]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Jul 24 10:16:12.332370 osdx ca-certificates[447520]: 1 added, 0 removed; done.
Jul 24 10:16:12.335299 osdx ca-certificates[447526]: Running hooks in /etc/ca-certificates/update.d...
Jul 24 10:16:12.338887 osdx ca-certificates[447528]: done.
Jul 24 10:16:12.443503 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Jul 24 10:16:12.452659 osdx cfgd[1923]: [414651]Completed change to active configuration
Jul 24 10:16:12.453212 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:16:12.467996 osdx dnscrypt-proxy[447584]: [2026-07-24 10:16:12] [NOTICE] dnscrypt-proxy 2.0.45
Jul 24 10:16:12.468271 osdx dnscrypt-proxy[447584]: [2026-07-24 10:16:12] [NOTICE] Network connectivity detected
Jul 24 10:16:12.468537 osdx dnscrypt-proxy[447584]: [2026-07-24 10:16:12] [NOTICE] Dropping privileges
Jul 24 10:16:12.471366 osdx dnscrypt-proxy[447584]: [2026-07-24 10:16:12] [NOTICE] Network connectivity detected
Jul 24 10:16:12.471452 osdx dnscrypt-proxy[447584]: [2026-07-24 10:16:12] [NOTICE] Now listening to 127.0.0.1:53 [UDP]
Jul 24 10:16:12.471452 osdx dnscrypt-proxy[447584]: [2026-07-24 10:16:12] [NOTICE] Now listening to 127.0.0.1:53 [TCP]
Jul 24 10:16:12.471452 osdx dnscrypt-proxy[447584]: [2026-07-24 10:16:12] [NOTICE] Firefox workaround initialized
Jul 24 10:16:12.471452 osdx dnscrypt-proxy[447584]: [2026-07-24 10:16:12] [NOTICE] Loading the set of cloaking rules from [/tmp/tmphf0qvtve]
Jul 24 10:16:12.478853 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.
Jul 24 10:16:12.607938 osdx dnscrypt-proxy[447584]: [2026-07-24 10:16:12] [NOTICE] [RD] OK (DoH) - rtt: 119ms
Jul 24 10:16:12.607938 osdx dnscrypt-proxy[447584]: [2026-07-24 10:16:12] [NOTICE] Server with the lowest initial latency: RD (rtt: 119ms)
Jul 24 10:16:12.607938 osdx dnscrypt-proxy[447584]: [2026-07-24 10:16:12] [NOTICE] dnscrypt-proxy is ready - live servers: 1

Step 4: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

DNSCrypt Server

Description

Configures DUT0 to connect, using DNSCrypt over an upstream server.

Scenario

Step 1: Run the command service dns proxy dnscrypt public-key running://dnscrypt.crt on DUT0 and expect the following output:

Show output
48:04:61:71:18:d9:24:fd:46:4f:dd:f9:88:99:37:da:f1:ca:f6:eb:51:14:93:33:06:66:c1:2a:0b:e1:e7:a7

Step 2: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy server-name RD
set service dns proxy static RD protocol dns-crypt ip 10.215.168.1
set service dns proxy static RD protocol dns-crypt port 8443
set service dns proxy static RD protocol dns-crypt provider name 2.dnscrypt-cert.remote.dns
set service dns proxy static RD protocol dns-crypt provider public-key '48:04:61:71:18:d9:24:fd:46:4f:dd:f9:88:99:37:da:f1:ca:f6:eb:51:14:93:33:06:66:c1:2a:0b:e1:e7:a7'
set service dns resolver local
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

(?m)^.*\[RD\] OK \(DNSCrypt\) - rtt: \d+ms$
Show output
Jul 24 10:16:18.362823 osdx systemd-journald[2180]: Runtime Journal (/run/log/journal/3a8dbab828fc40a183893e468c03e10b) is 1.8M, max 13.8M, 11.9M free.
Jul 24 10:16:18.366073 osdx systemd-journald[2180]: Received client request to rotate journal, rotating.
Jul 24 10:16:18.366148 osdx systemd-journald[2180]: Vacuuming done, freed 0B of archived journals from /run/log/journal/3a8dbab828fc40a183893e468c03e10b.
Jul 24 10:16:18.374828 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal clear'.
Jul 24 10:16:18.652016 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system coredump delete all'.
Jul 24 10:16:18.952934 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:16:19.059042 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Jul 24 10:16:19.128100 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Jul 24 10:16:19.250562 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'.
Jul 24 10:16:19.318127 osdx ubnt-cfgd[449357]: inactive
Jul 24 10:16:19.349839 osdx INFO[449366]: FRR daemons did not change
Jul 24 10:16:19.382070 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Jul 24 10:16:19.440319 osdx WARNING[449437]: No supported link modes on interface eth0
Jul 24 10:16:19.442215 osdx modulelauncher[449437]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Jul 24 10:16:19.442231 osdx modulelauncher[449437]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Jul 24 10:16:19.443947 osdx modulelauncher[449437]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --
Jul 24 10:16:19.443959 osdx modulelauncher[449437]: Command '/sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --' returned non-zero exit status 75.
Jul 24 10:16:19.668596 osdx cfgd[1923]: [414651]Completed change to active configuration
Jul 24 10:16:19.669206 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:16:19.699591 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.
Jul 24 10:16:19.844444 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Jul 24 10:16:19.912043 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal show | cat'.
Jul 24 10:16:20.075425 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'service dns proxy dnscrypt public-key running://dnscrypt.crt'.
Jul 24 10:16:20.235485 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:16:20.315524 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Jul 24 10:16:20.425550 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Jul 24 10:16:20.512927 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-crypt ip 10.215.168.1'.
Jul 24 10:16:20.580969 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-crypt port 8443'.
Jul 24 10:16:20.704156 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-crypt provider name 2.dnscrypt-cert.remote.dns'.
Jul 24 10:16:20.785434 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy static RD protocol dns-crypt provider public-key 48:04:61:71:18:d9:24:fd:46:4f:dd:f9:88:99:37:da:f1:ca:f6:eb:51:14:93:33:06:66:c1:2a:0b:e1:e7:a7'.
Jul 24 10:16:20.888273 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns resolver local'.
Jul 24 10:16:20.964101 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'.
Jul 24 10:16:21.082459 osdx ubnt-cfgd[449547]: inactive
Jul 24 10:16:21.108401 osdx INFO[449556]: FRR daemons did not change
Jul 24 10:16:21.122448 osdx ca-certificates[449572]: Updating certificates in /etc/ssl/certs...
Jul 24 10:16:21.688796 osdx ubnt-cfgd[450584]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Jul 24 10:16:21.697907 osdx ca-certificates[450590]: 1 added, 0 removed; done.
Jul 24 10:16:21.700832 osdx ca-certificates[450596]: Running hooks in /etc/ca-certificates/update.d...
Jul 24 10:16:21.703593 osdx ca-certificates[450598]: done.
Jul 24 10:16:21.802486 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Jul 24 10:16:21.812222 osdx cfgd[1923]: [414651]Completed change to active configuration
Jul 24 10:16:21.812717 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:16:21.832561 osdx dnscrypt-proxy[450654]: [2026-07-24 10:16:21] [NOTICE] dnscrypt-proxy 2.0.45
Jul 24 10:16:21.832753 osdx dnscrypt-proxy[450654]: [2026-07-24 10:16:21] [NOTICE] Network connectivity detected
Jul 24 10:16:21.832802 osdx dnscrypt-proxy[450654]: [2026-07-24 10:16:21] [NOTICE] Dropping privileges
Jul 24 10:16:21.835055 osdx dnscrypt-proxy[450654]: [2026-07-24 10:16:21] [NOTICE] Network connectivity detected
Jul 24 10:16:21.835107 osdx dnscrypt-proxy[450654]: [2026-07-24 10:16:21] [NOTICE] Now listening to 127.0.0.1:53 [UDP]
Jul 24 10:16:21.835107 osdx dnscrypt-proxy[450654]: [2026-07-24 10:16:21] [NOTICE] Now listening to 127.0.0.1:53 [TCP]
Jul 24 10:16:21.835107 osdx dnscrypt-proxy[450654]: [2026-07-24 10:16:21] [NOTICE] Firefox workaround initialized
Jul 24 10:16:21.835107 osdx dnscrypt-proxy[450654]: [2026-07-24 10:16:21] [NOTICE] Loading the set of cloaking rules from [/tmp/tmprvm315mg]
Jul 24 10:16:21.840058 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.
Jul 24 10:16:21.848779 osdx dnscrypt-proxy[450654]: [2026-07-24 10:16:21] [NOTICE] [RD] OK (DNSCrypt) - rtt: 13ms
Jul 24 10:16:21.848779 osdx dnscrypt-proxy[450654]: [2026-07-24 10:16:21] [NOTICE] Server with the lowest initial latency: RD (rtt: 13ms)
Jul 24 10:16:21.848862 osdx dnscrypt-proxy[450654]: [2026-07-24 10:16:21] [NOTICE] dnscrypt-proxy is ready - live servers: 1

Step 4: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16

DNSCrypt Server With Stamp

Description

Configures DUT0 to connect, using DNSCrypt over an upstream server (generating a DNS stamp and using it to configure the connection).

Scenario

Step 1: Run the command service dns proxy dnscrypt public-key running://dnscrypt.crt on DUT0 and expect the following output:

Show output
48:04:61:71:18:d9:24:fd:46:4f:dd:f9:88:99:37:da:f1:ca:f6:eb:51:14:93:33:06:66:c1:2a:0b:e1:e7:a7

Step 2: Run the command service dns proxy stamp calculate dns-crypt provider-name 2.dnscrypt-cert.remote.dns provider-key 48:04:61:71:18:d9:24:fd:46:4f:dd:f9:88:99:37:da:f1:ca:f6:eb:51:14:93:33:06:66:c1:2a:0b:e1:e7:a7 ip 10.215.168.1 port 8443 on DUT0 and expect the following output:

Show output
sdns://AQAAAAAAAAAAETEwLjIxNS4xNjguMTo4NDQzIEgEYXEY2ST9Rk_d-YiZN9rxyvbrURSTMwZmwSoL4eenGjIuZG5zY3J5cHQtY2VydC5yZW1vdGUuZG5z

Step 3: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set protocols static route 0.0.0.0/0 next-hop 10.215.168.1
set service dns proxy server-name RD
set service dns proxy static RD stamp 'sdns://AQAAAAAAAAAAETEwLjIxNS4xNjguMTo4NDQzIEgEYXEY2ST9Rk_d-YiZN9rxyvbrURSTMwZmwSoL4eenGjIuZG5zY3J5cHQtY2VydC5yZW1vdGUuZG5z'
set service dns resolver local
set system certificate trust 'running://remote.dns-server.crt'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 4: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

(?m)^.*\[RD\] OK \(DNSCrypt\) - rtt: \d+ms$
Show output
Jul 24 10:16:28.323925 osdx systemd-journald[2180]: Runtime Journal (/run/log/journal/3a8dbab828fc40a183893e468c03e10b) is 1.8M, max 13.8M, 11.9M free.
Jul 24 10:16:28.325716 osdx systemd-journald[2180]: Received client request to rotate journal, rotating.
Jul 24 10:16:28.325762 osdx systemd-journald[2180]: Vacuuming done, freed 0B of archived journals from /run/log/journal/3a8dbab828fc40a183893e468c03e10b.
Jul 24 10:16:28.335792 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal clear'.
Jul 24 10:16:28.543914 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system coredump delete all'.
Jul 24 10:16:28.790384 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:16:28.870853 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Jul 24 10:16:28.942229 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set protocols static route 0.0.0.0/0 next-hop 10.215.168.1'.
Jul 24 10:16:29.057351 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'.
Jul 24 10:16:29.112326 osdx ubnt-cfgd[452427]: inactive
Jul 24 10:16:29.135295 osdx INFO[452436]: FRR daemons did not change
Jul 24 10:16:29.161716 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Jul 24 10:16:29.211744 osdx WARNING[452507]: No supported link modes on interface eth0
Jul 24 10:16:29.213157 osdx modulelauncher[452507]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Jul 24 10:16:29.213169 osdx modulelauncher[452507]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Jul 24 10:16:29.214780 osdx modulelauncher[452507]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --
Jul 24 10:16:29.214787 osdx modulelauncher[452507]: Command '/sbin/ethtool -s eth0 autoneg on advertise Asym_Pause off Pause off --' returned non-zero exit status 75.
Jul 24 10:16:29.431364 osdx cfgd[1923]: [414651]Completed change to active configuration
Jul 24 10:16:29.431955 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:16:29.446666 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.
Jul 24 10:16:29.605366 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Jul 24 10:16:29.670999 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'system journal show | cat'.
Jul 24 10:16:29.800367 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'service dns proxy dnscrypt public-key running://dnscrypt.crt'.
Jul 24 10:16:29.915162 osdx OSDxCLI[414651]: User 'admin' executed a new command: 'service dns proxy stamp calculate dns-crypt provider-name 2.dnscrypt-cert.remote.dns provider-key 48:04:61:71:18:d9:24:fd:46:4f:dd:f9:88:99:37:da:f1:ca:f6:eb:51:14:93:33:06:66:c1:2a:0b:e1:e7:a7 ip 10.215.168.1 port 8443'.
Jul 24 10:16:30.046877 osdx OSDxCLI[414651]: User 'admin' entered the configuration menu.
Jul 24 10:16:30.111282 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set system certificate trust running://remote.dns-server.crt'.
Jul 24 10:16:30.216387 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy server-name RD'.
Jul 24 10:16:30.280162 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns proxy static RD stamp sdns://AQAAAAAAAAAAETEwLjIxNS4xNjguMTo4NDQzIEgEYXEY2ST9Rk_d-YiZN9rxyvbrURSTMwZmwSoL4eenGjIuZG5zY3J5cHQtY2VydC5yZW1vdGUuZG5z'.
Jul 24 10:16:30.368794 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'set service dns resolver local'.
Jul 24 10:16:30.434653 osdx OSDxCLI[414651]: User 'admin' added a new cfg line: 'show working'.
Jul 24 10:16:30.525919 osdx ubnt-cfgd[452617]: inactive
Jul 24 10:16:30.548455 osdx INFO[452626]: FRR daemons did not change
Jul 24 10:16:30.560457 osdx ca-certificates[452641]: Updating certificates in /etc/ssl/certs...
Jul 24 10:16:31.103000 osdx ubnt-cfgd[453654]: rehash: warning: skipping ca-certificates.crt,it does not contain exactly one certificate or CRL
Jul 24 10:16:31.113684 osdx ca-certificates[453659]: 1 added, 0 removed; done.
Jul 24 10:16:31.117512 osdx ca-certificates[453666]: Running hooks in /etc/ca-certificates/update.d...
Jul 24 10:16:31.121189 osdx ca-certificates[453668]: done.
Jul 24 10:16:31.222076 osdx systemd[1]: Started dnscrypt-proxy.service - DNSCrypt client proxy.
Jul 24 10:16:31.230012 osdx cfgd[1923]: [414651]Completed change to active configuration
Jul 24 10:16:31.230641 osdx OSDxCLI[414651]: User 'admin' committed the configuration.
Jul 24 10:16:31.242645 osdx dnscrypt-proxy[453724]: [2026-07-24 10:16:31] [NOTICE] dnscrypt-proxy 2.0.45
Jul 24 10:16:31.242964 osdx dnscrypt-proxy[453724]: [2026-07-24 10:16:31] [NOTICE] Network connectivity detected
Jul 24 10:16:31.242991 osdx dnscrypt-proxy[453724]: [2026-07-24 10:16:31] [NOTICE] Dropping privileges
Jul 24 10:16:31.245167 osdx dnscrypt-proxy[453724]: [2026-07-24 10:16:31] [NOTICE] Network connectivity detected
Jul 24 10:16:31.245213 osdx dnscrypt-proxy[453724]: [2026-07-24 10:16:31] [NOTICE] Now listening to 127.0.0.1:53 [UDP]
Jul 24 10:16:31.245213 osdx dnscrypt-proxy[453724]: [2026-07-24 10:16:31] [NOTICE] Now listening to 127.0.0.1:53 [TCP]
Jul 24 10:16:31.245213 osdx dnscrypt-proxy[453724]: [2026-07-24 10:16:31] [NOTICE] Firefox workaround initialized
Jul 24 10:16:31.245213 osdx dnscrypt-proxy[453724]: [2026-07-24 10:16:31] [NOTICE] Loading the set of cloaking rules from [/tmp/tmpltped0s1]
Jul 24 10:16:31.253642 osdx dnscrypt-proxy[453724]: [2026-07-24 10:16:31] [NOTICE] [RD] OK (DNSCrypt) - rtt: 7ms
Jul 24 10:16:31.253642 osdx dnscrypt-proxy[453724]: [2026-07-24 10:16:31] [NOTICE] Server with the lowest initial latency: RD (rtt: 7ms)
Jul 24 10:16:31.253642 osdx dnscrypt-proxy[453724]: [2026-07-24 10:16:31] [NOTICE] dnscrypt-proxy is ready - live servers: 1
Jul 24 10:16:31.257766 osdx OSDxCLI[414651]: User 'admin' left the configuration menu.

Step 5: Run the command show host lookup teldat.com type A on DUT0 and check whether the output contains the following tokens:

teldat.com has address 19.18.17.16
Show output
;; communications error to ::1#53: connection refused
;; communications error to ::1#53: connection refused
teldat.com has address 19.18.17.16